Processed: force merge all bugs around the broken build-conflict

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Just found the two other bugs about the issue forcemerge 495246 495108 496532 Bug#495246: version syntax error in Build-Conflicts (unexpanded substvar ${Source-Version}) Bug#495108: xosd source package control info contains unexpanded variable

Bug#496748: jppy: Missing dependency on python-vobject

2008-08-27 Thread Alexander Wirt
Package: jppy Version: 0.0.47-1 Severity: grave Justification: renders package unusable Subject says it all: jppy Traceback (most recent call last): File /usr/bin/jppy, line 3, in module import jppy File /var/lib/python-support/python2.5/jppy/__init__.py, line 35, in module from

Bug#495209: marked as done (still fails to build on ia64)

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 06:32:03 + with message-id [EMAIL PROTECTED] and subject line Bug#495209: fixed in guile-1.8 1.8.5+1-4 has caused the Debian Bug report #495209, regarding still fails to build on ia64 to be marked as done. This means that you claim that the problem has

Bug#496375: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Julien Valroff
Hi Alexander, Many thanks for your email. I have been willing to review rkhunter bugs before submitting it. Le mercredi 27 août 2008 à 04:00 +0400, Solar Designer a écrit : FWIW, I happened to independently notice this and report it upstream a week ago:

Bug#496403: mgetty insecure temp file usage

2008-08-27 Thread Tomas Hoger
Hi Thijs! # get unique directory name, using faxq-helper This does not seem to be much of an issue beyond DoS, right? mkdir returns an error when $spooldir already exists. Yeah, 'mktemp -t -d' looks like a better alternative though... # if filename is -, use stdin I noticed that following

Processed: tagging 490910

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.9.26 tags 490910 + pending Bug#490910: linux-2.6: CVE-2008-0598 information disclosure Tags were: patch security Tags added: pending End of message, stopping processing here. Please

Processed: merge

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: merge 496558 496678 Bug#496558: nautilus: Fails to browse Bug#496678: nautilus: Fails to start Merged 496558 496678. thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator,

Processed: ...

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 496558 +confirmed Bug#496558: nautilus: Fails to browse There were no tags set. Bug#496678: nautilus: Fails to start Tags added: confirmed thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system

Bug#496375: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Solar Designer
On Wed, Aug 27, 2008 at 09:06:58AM +0200, Julien Valroff wrote: Do you suggest that using /var/run/rkhunter-debug is better than /tmp/rkhunter-debug. (created using mktemp)? Yes - primarily from usability standpoint. This time, having a fixed filename is better, and since rkhunter

Bug#496558: nautilus: Fails to browser - confirmed

2008-08-27 Thread Dieter Faulbaum
I found this error too (but on a etch version). And it seems to me that the last (security) upgrade of libxml2 and/or libmxl2-utils caused this error. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#496558: nautilus: Fails to browser - confirmed

2008-08-27 Thread Stephan Peijnik
On Wed, 27 Aug 2008 10:33:13 +0200, Dieter Faulbaum [EMAIL PROTECTED] wrote: I found this error too (but on a etch version). And it seems to me that the last (security) upgrade of libxml2 and/or libmxl2-utils caused this error. Could you please provide the exact version number of your

Bug#493667: nfs-common: nfs quite broken

2008-08-27 Thread Vincent Danjean
Hi, I experiment the same problem in my lab which has an etch nfs server. When stations are upgraded to nfs-common 1:1.1.3-1, users cannot access their files. Adding sec=sys to the client's mount options fix the problem. As I found the fix in Debian bug report, I did not make yet another

Bug#496758: Too late for lenny

2008-08-27 Thread Goswin von Brederlow
Package: ia32-libs-tools Version: 12 Severity: critical This is just a reminder notice to stop any migrating to lenny. It took way too long to get ia32-libs-tools through NEW and there just isn't enough time left to get this tested and fixed properly. Do not include ia32-libs-tools in lenny.

Bug#496625: Problem with multicast communication (plus solution)

2008-08-27 Thread Piotr Meyer
On Tue, Aug 26, 2008 at 11:52:18AM -0500, Eric Evans wrote: Yes, you are correct. A fix for this was incorporated into the final release (1.5), which I uploaded to unstable last night. If you are in a position to test it, any feedback would be appreciated. I test ucarp 1.5-1 from unstable

Bug#495354: [DebianGIS-dev] Bug#495354: gdalinfo segfaults on a 6.2Mib netCDF file

2008-08-27 Thread Francesco P. Lovergine
severity 495354 normal thanks This is not grave, the package is perfectly usable with many other formats. I will investigate with upstream about that. Also consider that netcdf support is partially broken because hdf4 is historically built in a not completely gdal-compliant way. That's is solved

Processed: Re: [DebianGIS-dev] Bug#495354: gdalinfo segfaults on a 6.2Mib netCDF file

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: severity 495354 normal Bug#495354: gdalinfo segfaults on a 6.2Mib netCDF file Bug#495353: gdal-bin: gdalinfo segfaults on a 6.2Mib netCDF file Severity set to `normal' from `grave' thanks Stopping processing here. Please contact me if you need

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: severity 496382 normal Bug#496382: The possibility of attack with the help of symlinks in some Debian packages Severity set to `normal' from `grave' thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking

Bug#496122: new upstream version of libfile-sharedir-perl

2008-08-27 Thread Ansgar Burchardt
Hi, libfile-sharedir-perl has a currently a grave bug because the directory layout used to store data has changed. This means the package is unusable for Perl distributions whose name contains a - and a recent Module::Install (= 0.76, released on 17 Jul 2008 and included in Lenny), see #496122.

Bug#496265: marked as done (vlc: buffer overflow in mms handling)

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 09:47:13 + with message-id [EMAIL PROTECTED] and subject line Bug#496265: fixed in vlc 0.8.6.i-2 has caused the Debian Bug report #496265, regarding vlc: buffer overflow in mms handling to be marked as done. This means that you claim that the problem has

Bug#495712: wine: does not start

2008-08-27 Thread Moritz Muehlenhoff
On Tue, Aug 19, 2008 at 11:21:52PM +0200, M. KLEIN wrote: Package: wine Version: 1.0.0-1 Severity: grave Justification: renders package unusable [EN] Any wine* commande (wine, winecfg ...) produces the following message, but nothing else append: /usr/bin/wine: line 63:

Bug#496382: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Moritz Muehlenhoff
severity 496382 normal thanks On Sun, Aug 24, 2008 at 10:05:30PM +0400, Dmitry E. Oboukhov wrote: Package: bulmages-servers Severity: grave Binary-package: bulmages-servers (0.11.1-2) file: /usr/share/bulmages/examples/scripts/actualizabulmacont file:

Processed: Remove forwarded tag

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # The upstream bug is for xmonad, and this issue is unrelated. notforwarded 496677 Bug#496677: Cairo backend unusable on 64-bit architectures Removed annotation that Bug had been forwarded to https://savannah.gnu.org/bugs/index.php?24083. thanks

Processed: update found field...

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # as reported by Dieter Faulbaum... found 496558 2.4.13-11+b1 Bug#496558: nautilus: Fails to browse Bug#496678: nautilus: Fails to start Bug marked as found in version 2.4.13-11+b1. thanks Stopping processing here. Please contact me if you need

Bug#493883: marked as done ([manpages-it] Uninstallable due to overwrite try of /usr/share/man/it/man1/hman.1.gz)

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 11:17:03 + with message-id [EMAIL PROTECTED] and subject line Bug#493883: fixed in man-pages-it 2.80-3 has caused the Debian Bug report #493883, regarding [manpages-it] Uninstallable due to overwrite try of /usr/share/man/it/man1/hman.1.gz to be marked as

Bug#471404: Wouldn't a 32bit bin86 be usefull?

2008-08-27 Thread Goswin von Brederlow
Hi, wouldn't it make sense to compile bin86 with -m32 on amd64? People might still want to build 16bit code for example for a boot loader. MfG Goswin -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#332782: Release Notes: license clarification

2008-08-27 Thread Osamu Aoki
On Tue, Aug 26, 2008 at 09:58:25PM +0200, Josip Rodin wrote: On Tue, Aug 26, 2008 at 07:26:38PM +0200, Luk Claes wrote: But, in such an (unlikely) court battle the onus would be on them to prove that the stuff they committed was both copyrightable in the first place as well as not

Processed: newsbeuter installability

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # libmrss0 is not installable; can be fixed by rebuild from source severity 496774 serious Bug#496774: libmrss0: depends on a nonexistent package Severity set to `serious' from `normal' # newsbeuter has been built against the problematic libmrss0

Bug#496363: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Thijs Kinkhorst
Hi Dirk, On Monday 25 August 2008 13:57, Dirk Eddelbuettel wrote: Upstream covers more than just Linux distros: Aix, Solaris, OS X, HP-UX, ... and even Windoze (though the javareconf script may not matter there). But I just emailed the point person for javareconf. Maybe we can move creation

Processed: confirmed, let's remove it instead

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 496437 confirmed Bug#496437: The possibility of attack with the help of symlinks in some Debian packages Tags were: security Tags added: confirmed thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking

Bug#496437: confirmed, let's remove it instead

2008-08-27 Thread Thijs Kinkhorst
tags 496437 confirmed thanks I confirmed that the package is full of insecure temp files. However given that it's orphaned and has several problems, I'm asking for removal from unstable. Thijs pgp3m15STSoXo.pgp Description: PGP signature

Bug#496357: opensync-plugin-palm: Impossible to install the package

2008-08-27 Thread Michael Banck
On Sun, Aug 24, 2008 at 08:04:44PM +0200, nb wrote: When I try to install the package, I have the following error : Package: opensync-plugin-palm [...] Sorry, but that's no error, that's the apt-cache output. Can you please post the error you get? thanks, Michael -- To UNSUBSCRIBE,

Bug#496363: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Dirk Eddelbuettel
Hi Thijs, On 27 August 2008 at 13:57, Thijs Kinkhorst wrote: | Hi Dirk, | | On Monday 25 August 2008 13:57, Dirk Eddelbuettel wrote: | Upstream covers more than just Linux distros: Aix, Solaris, OS X, HP-UX, | ... and even Windoze (though the javareconf script may not matter there). | | But

Processed: confirmed to be present

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 496427 confirmed Bug#496427: The possibility of attack with the help of symlinks in some Debian packages Tags were: security Tags added: confirmed thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking

Bug#496427: confirmed to be present

2008-08-27 Thread Thijs Kinkhorst
tags 496427 confirmed thanks Indeed present, a simple grep yields a number of different results already, see below. As the code contains many instances of different things written to /tmp, it may make sense to resolve that by creating one private working dir securely, and then prefixing that

Bug#496371: [Pkg-lustre-maintainers] Bug#496371: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Patrick Winnertz
Hello Dmitry, Thanks for your test, but atm I've some problems to fix this issue for lustre- tests In some packages I've discovered scripts with errors which may be used by a user for damaging important system files or user's files. For example if a script uses in its work a temp file which is

Bug#496433: this is indeed present

2008-08-27 Thread Thijs Kinkhorst
tags 496433 confirmed thanks Hi, Indeed, several times the file /tmp/audiolink.db.tmp gets used in code/audiolink. This is probably easily fixable through using the Perl::Temp module and its mktemp() funtion to create a secure file once, (re)use that on the several needed occasions and remove

Bug#481134: Please hint poppler-data for lenny inclusion

2008-08-27 Thread Hideki Yamane
On Sun, 24 Aug 2008 08:32:21 +0200 Christian Perrier [EMAIL PROTECTED] wrote: Also don't forget about suggesting to add it to the CJK languages -desktop tasks in tasksel, if it is that important. I think that non-free packages can be added there... That's very very helpful for our users!

Processed: this is indeed present

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 496433 confirmed Bug#496433: The possibility of attack with the help of symlinks in some Debian packages Tags were: security Tags added: confirmed thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking

Bug#496419: issue is present, code runs as root

2008-08-27 Thread Thijs Kinkhorst
tags 496419 confirmed thanks Hi, A simple grep revealed a lot of tempfile issues here, see below. As far as I understand it, the code runs as root. This makes the issue quite serious. Please make sure this is fixed before lenny is released. As several different temp files are used insecurely,

Processed: issue is present, code runs as root

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 496419 confirmed Bug#496419: The possibility of attack with the help of symlinks in some Debian packages Tags were: security Tags added: confirmed thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking

Bug#481134: Please hint poppler-data for lenny inclusion

2008-08-27 Thread Hideki Yamane
On Sun, 24 Aug 2008 19:45:13 +0200 Luk Claes [EMAIL PROTECTED] wrote: unblocked Great thanks Luk! But, verrry sooorry, I've updated this poppler-data package before read this mail... changelog is below, 1 bug fix and trivial changes. poppler-data (0.2.0-2) unstable; urgency=low *

Bug#496582: gnome-app-install: Application hangs while searching for a package

2008-08-27 Thread Julian Andres Klode
reassign 496582 librsvg2-2 2.22.2-2 severity 496582 important Am Mittwoch, den 27.08.2008, 00:13 +0200 schrieb Jose Pablo Ferrero: The problem occurs when showing some icons (i.e. elisa.svg). Trying to open elisa.svg (/usr/share/app-install/icons/) with gpaint or gimp cause a segmentation

Processed (with 5 errors): Re: Bug#496582: gnome-app-install: Application hangs while searching for a package

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: reassign 496582 librsvg2-2 2.22.2-2 Bug#496582: gnome-app-install: Application hangs while searching for a package Bug reassigned from package `gnome-app-install' to `librsvg2-2'. severity 496582 important Bug#496582: gnome-app-install: Application

Processed: retitle 494468 to Postinst violates Debian policy (10.7.3) by not preserving changes to /etc/locale.gen

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.33 retitle 494468 Postinst violates Debian policy (10.7.3) by not preserving changes to /etc/locale.gen Bug#494468: locales: Postist violates Debian policy (10.7.3) by not preserving

Bug#496371: [Pkg-lustre-maintainers] Bug#496371: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Stephen Gran
This one time, at band camp, Patrick Winnertz said: I guess the part which is critical is this one: tmpfile=$(mktemp /tmp/iozone.XX) ---snip-- while date; do LOOP=`expr $LOOP + 1` echo Test #$LOOP iozone $VERIFY $ODIR -r $REC -i 0 -i 1 -f

Bug#496363: marked as done (The possibility of attack with the help of symlinks in some Debian packages)

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 13:02:13 + with message-id [EMAIL PROTECTED] and subject line Bug#496363: fixed in r-base-core-ra 1.1.1-2 has caused the Debian Bug report #496363, regarding The possibility of attack with the help of symlinks in some Debian packages to be marked as done.

Bug#496371: [Pkg-lustre-maintainers] Bug#496371: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Dmitry E. Oboukhov
SG tmpfile=$(mktemp /tmp/iozone.XX) use 'mktemp -t iozone.XX' instead 'mktemp /tmp/iozone.XX' -- ... mpd paused: Manowar - Gloves of Metal . ''`. Dmitry E. Oboukhov : :’ : [EMAIL PROTECTED] `. `~’ GPGKey: 1024D / F8E26537 2006-11-21 `- 1B23 D4F8 8EC0 D902 0555 E438

Processed: your mail

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: forwarded 496414 http://bugzilla.scilab.org/show_bug.cgi?id=3409 Bug#496414: The possibility of attack with the help of symlinks in some Debian packages Noted your statement that Bug has been forwarded to

Bug#483337: intent to NMU

2008-08-27 Thread Nico Golde
Hi, a patch to fix this is attached and archived on: http://people.debian.org/~nion/nmu-diff/mt-daapd-0.9~r1696-1.3_0.9~r1696-1.4.patch Kind regards Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13

Processed: reassign 496774 to newsbeuter

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.35 reassign 496774 newsbeuter Bug#496774: libmrss0: depends on a nonexistent package Bug reassigned from package `libmrss0' to `newsbeuter'. End of message, stopping processing here.

Bug#496772: newsbeuter: depends on a nonexistent package

2008-08-27 Thread Nico Golde
Hi Riccardo, * Riccardo Stagni [EMAIL PROTECTED] [2008-08-27 13:53]: [...] (I filed a similar bugreport against libmrss0. If you think it's a fault in libnxml, please reassign/merge as appropriate) I reassigned this one back to newsbeuter as it is only newsbeuters fault calling

Bug#482140: (pas de sujet)

2008-08-27 Thread 01
I experienced the same problem with my notebook. Using Etch Stable (installed from the CD), then upgrading to Lenny (to get my Intel GMA965 chipset working well with 3D). I've got a 32 bits Intel architecture (CPU = pentium M) I solved the problem by : - editing my /etc/apt/sources.list to

Bug#481134: Please hint poppler-data for lenny inclusion

2008-08-27 Thread Christian Perrier
Hideki Yamane a écrit : So I and other Japanese Debian developer/maintainer/package maintainer/ users want poppler-data package to there, the CJK languages-desktop tasks in tasksel. Please consider that. The easiest way to have this to happen is by sending a wishlist bug report against

Bug#496640: marked as done (anon-proxy: fails to install if /etc/environment is empty)

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 13:32:03 + with message-id [EMAIL PROTECTED] and subject line Bug#496640: fixed in anon-proxy 00.05.38+20080710-2 has caused the Debian Bug report #496640, regarding anon-proxy: fails to install if /etc/environment is empty to be marked as done. This means

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 496395 confirmed patch Bug#496395: The possibility of attack with the help of symlinks in some Debian packages Tags were: security Tags added: confirmed, patch thanks Stopping processing here. Please contact me if you need assistance. Debian

Bug#481134: Please hint poppler-data for lenny inclusion

2008-08-27 Thread Deng Xiyue
在 2008-08-27三的 15:58 +0200,Christian Perrier写道: Hideki Yamane a écrit : So I and other Japanese Debian developer/maintainer/package maintainer/ users want poppler-data package to there, the CJK languages-desktop tasks in tasksel. Please consider that. The easiest way to have this

Bug#496001: marked as done (python-coverage: Missing Depends: python-pkg-resources)

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 13:32:06 + with message-id [EMAIL PROTECTED] and subject line Bug#496001: fixed in python-coverage 2.80-2 has caused the Debian Bug report #496001, regarding python-coverage: Missing Depends: python-pkg-resources to be marked as done. This means that you

Bug#496395: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Moritz Muehlenhoff
tags 496395 confirmed patch thanks Dmitry E. Oboukhov wrote: Package: apertium Severity: grave Hi, maintainer! This message about the error concerns a few packages at once. I've tested all the packages (for Lenny) on my Debian mirror. All scripts of packages (marked as executable)

Processed: tagging 417142

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.29~bpo40+1 tags 417142 pending Bug#417142: depends on non-essential package debconf in postrm Tags were: patch etch-ignore Tags added: pending End of message, stopping processing here.

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: severity 496402 normal Bug#496402: The possibility of attack with the help of symlinks in some Debian packages Severity set to `normal' from `grave' thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking

Bug#417142: NMU for websvn

2008-08-27 Thread Thijs Kinkhorst
Hi Pierre, This RC bug has now been open for two weeks. I'm uploading an NMU to the delayed-5 queue according to the attached patch. I hope this helps to keep websvn in good shape in lenny. cheers, Thijs diff -u websvn-2.0/debian/changelog websvn-2.0/debian/changelog ---

Bug#496402: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Moritz Muehlenhoff
severity 496402 normal thanks On Sun, Aug 24, 2008 at 10:05:29PM +0400, Dmitry E. Oboukhov wrote: Package: aegis Severity: grave Hi, maintainer! This message about the error concerns a few packages at once. I've tested all the packages (for Lenny) on my Debian mirror. All scripts

Bug#483337: marked as done (mt-daapd: FTBFS: scan-mpc.c:73: error: too many arguments to function 'taglib_tag_free_strings')

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 14:02:03 + with message-id [EMAIL PROTECTED] and subject line Bug#483337: fixed in mt-daapd 0.9~r1696-1.4 has caused the Debian Bug report #483337, regarding mt-daapd: FTBFS: scan-mpc.c:73: error: too many arguments to function 'taglib_tag_free_strings' to

Bug#496371: [Pkg-lustre-maintainers] Bug#496371: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Stephen Gran
This one time, at band camp, Patrick Winnertz said: Thanks Stephen, tmpfile=$(mktemp /tmp/iozone.XX) I know that this way it is possible. But as the user should find the log afterwards I would prefer to use /tmp/iozone.log or something else, nothing random. But as I wrote in my

Processed: severity of 495968 is grave

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.35 severity 495968 grave Bug#495968: [gpicview] security RC bugs Severity set to `grave' from `grave' End of message, stopping processing here. Please contact me if you need

Processed: severity of 495968 is grave

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.35 severity 495968 grave Bug#495968: [gpicview] security RC bugs Severity set to `grave' from `serious' End of message, stopping processing here. Please contact me if you need

Bug#496217: marked as done (mt-daapd: admin page password always fails)

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 14:02:03 + with message-id [EMAIL PROTECTED] and subject line Bug#496217: fixed in mt-daapd 0.9~r1696-1.4 has caused the Debian Bug report #496217, regarding mt-daapd: admin page password always fails to be marked as done. This means that you claim that

Processed: tagging 491655

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.35 tags 491655 pending Bug#491655: audacious: log file spammed with tuple_get_int assertion failure message Tags were: patch Tags added: pending End of message, stopping processing

Bug#496799: imp4: cyrus.php file missing

2008-08-27 Thread pmunoz
Package: imp4 Version: 4.2-1 Severity: grave Justification: renders package unusable The file /usr/share/horde3/imp/lib/Quota/cyrus.php has been removed from horde3 (checked hord3 CVS website, stating courier.php and cyrus.php have been merged somehow). However some imp functions still use

Bug#464281: marked as done (adept: FTBFS: libtool: link: cannot find the library `/usr/lib/libept.la' or unhandled argument `/usr/lib/libept.la')

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 16:49:28 +0200 with message-id [EMAIL PROTECTED] and subject line No longer applies. has caused the Debian Bug report #464281, regarding adept: FTBFS: libtool: link: cannot find the library `/usr/lib/libept.la' or unhandled argument `/usr/lib/libept.la' to be

Bug#495154: Processed: RM: tmsnc/testing -- ROM; project discontinued upstream

2008-08-27 Thread Thomas Viehmann
Hi Miriam, Debian Bug Tracking System wrote: Bug#495154: tmsnc: Package should not go into stable Changed Bug title to `RM: tmsnc/testing -- ROM; project discontinued upstream' from `tmsnc: Package should not go into stable'. based on the bug report, it looks like the release team would

Bug#495968: [gpicview] security RC bugs

2008-08-27 Thread Nico Golde
Hi, [2] [ 2019485 ] gpicview ask_before_save is ignored with LIBJPEG [3] [ 2019492 ] gpicview ask_before_save is ignored if auto_save_rotated those are no security bugs, there is no way for another user to exploit this. Those are just normal application bugs. Kind regards Nico -- Nico Golde -

Processed: No longer applies.

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: fixed 464281 3.0~beta1 Bug#464281: adept: FTBFS: libtool: link: cannot find the library `/usr/lib/libept.la' or unhandled argument `/usr/lib/libept.la' Bug marked as fixed in version 3.0~beta1. thanks Stopping processing here. Please contact me if

Bug#491655: how about fixing this in a Debian revision / NMU

2008-08-27 Thread Thomas Viehmann
Hi, Luk Claes wrote: Yes, I think it's worth fixing. as not much seems to have happened in for a week (particularly not on Friday), I'll be aiming at a NMU on Saturday. That should also give the maintainers some breathing-room to consider what else they're planning to do. Kind regards T. --

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 496436 patch confirmed Bug#496436: The possibility of attack with the help of symlinks in some Debian packages Tags were: security Tags added: patch, confirmed thanks Stopping processing here. Please contact me if you need assistance. Debian

Bug#496436: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Moritz Muehlenhoff
tags 496436 patch confirmed thanks Dmitry E. Oboukhov wrote: Package: gpsdrive-scripts Severity: grave Hi, maintainer! This message about the error concerns a few packages at once. I've tested all the packages (for Lenny) on my Debian mirror. All scripts of packages (marked as

Bug#495154: Processed: RM: tmsnc/testing -- ROM; project discontinued upstream

2008-08-27 Thread Miriam Ruiz
2008/8/27 Thomas Viehmann [EMAIL PROTECTED]: Hi Miriam, Debian Bug Tracking System wrote: Bug#495154: tmsnc: Package should not go into stable Changed Bug title to `RM: tmsnc/testing -- ROM; project discontinued upstream' from `tmsnc: Package should not go into stable'. based on the bug

Bug#496803: util-vserver: system hang when shutting down host

2008-08-27 Thread Adam Borowski
Package: util-vserver Version: 0.30.216~r2772-1 Severity: grave Tags: patch Justification: causes non-serious data loss I'm afraid that /etc/init.d/util-vserver stop hangs if there is at least one guest running; it's usually called on host shutdown when it will block the whole system from

Bug#417142: NMU for websvn

2008-08-27 Thread Pierre Chifflier
On Wed, Aug 27, 2008 at 04:10:06PM +0200, Thijs Kinkhorst wrote: Hi Pierre, This RC bug has now been open for two weeks. I'm uploading an NMU to the delayed-5 queue according to the attached patch. I hope this helps to keep websvn in good shape in lenny. Hi Thijs, I'm merging your

Bug#491655: [Pkg-audacious-maintainers] Bug#491655: how about fixing this in a Debian revision / NMU

2008-08-27 Thread William Pitcock
On Wed, 2008-08-27 at 16:52 +0200, Thomas Viehmann wrote: Hi, Luk Claes wrote: Yes, I think it's worth fixing. as not much seems to have happened in for a week (particularly not on Friday), I'll be aiming at a NMU on Saturday. That should also give the maintainers some breathing-room to

Processed: reopening sympa tmp races

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: reopen 494969 Bug#494969: sympa: Leftover debug code may lead to data loss 'reopen' may be inappropriate when a bug has been closed with a version; you may need to use 'found' to remove fixed versions. Bug#496405: The possibility of attack with the help

Processed: Re: Bug#496410: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: severity 496410 important Bug#496410: The possibility of attack with the help of symlinks in some Debian packages Severity set to `important' from `grave' thanks Stopping processing here. Please contact me if you need assistance. Debian bug

Bug#496410: The possibility of attack with the help of symlinks in some Debian packages

2008-08-27 Thread Bastian Blank
severity 496410 important thanks On Wed, Aug 27, 2008 at 07:12:29PM +0400, Dmitry E. Oboukhov wrote: _or_ _causes_ _data_ _loss_ It does not cause data loss, the admin needs to execute it. And now stop bitching around. Bastian -- Superior ability breeds superior ambition. --

Processed: Re: Bug#495154: Processed: RM: tmsnc/testing -- ROM; project discontinued upstream

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: retitle 495154 RM: tmsnc -- ROM; project discontinued upstream Bug#495154: RM: tmsnc/testing -- ROM; project discontinued upstream Changed Bug title to `RM: tmsnc -- ROM; project discontinued upstream' from `RM: tmsnc/testing -- ROM; project

Bug#417142: marked as done (depends on non-essential package debconf in postrm)

2008-08-27 Thread Debian Bug Tracking System
Your message dated Wed, 27 Aug 2008 15:17:05 + with message-id [EMAIL PROTECTED] and subject line Bug#417142: fixed in websvn 2.0-3 has caused the Debian Bug report #417142, regarding depends on non-essential package debconf in postrm to be marked as done. This means that you claim that the

Bug#495154: Processed: RM: tmsnc/testing -- ROM; project discontinued upstream

2008-08-27 Thread Thomas Viehmann
retitle 495154 RM: tmsnc -- ROM; project discontinued upstream thanks Miriam Ruiz wrote: It would be better to remove it both from testing AND unstable. It makes no sense to keep maintaining it in Debian at all. Will do. Thanks for the quick reply! Kind regards T. -- Thomas Viehmann,

Bug#491655: [Pkg-audacious-maintainers] Bug#491655: how about fixing this in a Debian revision / NMU

2008-08-27 Thread Thomas Viehmann
William Pitcock wrote: I am not upload enabled at the moment, please proceed with the NMU. You might take a look at some of the other patches and see if they are worthwhile to include in the NMU too. If you can whip up a short MU for sponsoring, we could also go with that. Otherwise, I'd

Bug#496807: gnucash: silently removes main files while trying to save without lock

2008-08-27 Thread Bas Wijnen
Package: gnucash Version: 2.2.6-1 Severity: grave Justification: causes data loss I was trying to use gnucash over sshfs, to allow several machines to handle the same file. It complained that it was unable to get a lock, and so couldn't prevent simultaneous writes. This was no problem, because

Bug#491270: bug has been pending for three weeks

2008-08-27 Thread Thomas Viehmann
Hi, this (RC!) bug has been pending for three weeks now. Unless there are objections, I should think that August is a good month to have a fix uploaded and will see to that if noone else does. Kind regards T. -- Thomas Viehmann, http://thomas.viehmann.net/ -- To UNSUBSCRIBE, email to

Bug#491655: [Pkg-audacious-maintainers] Bug#491655: how about fixing this in a Debian revision / NMU

2008-08-27 Thread William Pitcock
Hi, On Wed, 2008-08-27 at 17:40 +0200, Thomas Viehmann wrote: William Pitcock wrote: I am not upload enabled at the moment, please proceed with the NMU. You might take a look at some of the other patches and see if they are worthwhile to include in the NMU too. If you can whip up a

Bug#496808: ruby1.8: DoS vulnerability in rexml parsing module

2008-08-27 Thread Frank Louwers
Package: ruby1.8 Version: 1.8.5-4etch2 Severity: grave Tags: security Justification: user security hole The rexml lib is vulnerable to a DoS attack. Please see http://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml/. I know there isn't an official patch yet (except the

Bug#496807: gnucash: silently removes main files while trying to save without lock

2008-08-27 Thread Micha Lenk
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 forwarded 496807 http://bugzilla.gnome.org/show_bug.cgi?id=549595 thanks Hi Bas, thank you for your feedback on Gnucash. I have forwarded your report to the upstream bug tracker as http://bugzilla.gnome.org/show_bug.cgi?id=549595 Regards Micha

Processed: Re: Bug#496807: gnucash: silently removes main files while trying to save without lock

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: forwarded 496807 http://bugzilla.gnome.org/show_bug.cgi?id=549595 Bug#496807: gnucash: silently removes main files while trying to save without lock Noted your statement that Bug has been forwarded to http://bugzilla.gnome.org/show_bug.cgi?id=549595.

Bug#496808: ruby1.8: DoS vulnerability in rexml parsing module

2008-08-27 Thread Thijs Kinkhorst
On Wednesday 27 August 2008 17:56, Frank Louwers wrote: The rexml lib is vulnerable to a DoS attack. Please see http://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml/. This is CVE-2008-3790. Please mention it in the package changelog on uploads. Thijs pgpish8KyIIkh.pgp

Bug#493217: libnfsidmap-0.21 is available

2008-08-27 Thread Steve Dickson
Kevin Coffman wrote: --- libnfsidmap-0.21/libnfsidmap.c~ 2008-08-02 10:52:00.289845221 +1200 +++ libnfsidmap-0.21/libnfsidmap.c 2008-08-02 10:47:50.647889312 +1200 @@ -101,7 +101,7 @@ char plgname[128]; int ret = 0; - snprintf(plgname, sizeof(plgname), %s%s.so,

Bug#496810: initscript nsca fails when invocked with start and already running

2008-08-27 Thread Vincent Danjean
Package: nsca Version: 2.6-3.2 Severity: serious Hi, you should add in README.Debian that dpkg-reconfigure nsca is needed to install startup links (I discovered it by looking at /var/lib/dpkg/info/nsca.postinst..., not something usual users want to do). README.Debian currently says : by

Bug#451791: closed by Julien Cristau [EMAIL PROTECTED] (Bug#451791: fixed in xserver-xorg-video-intel 2:2.3.2-2+lenny3)

2008-08-27 Thread Mike Hommey
[ Brice Goglin ] * Add 02_xaa_by_default_on_i965.diff to switch back to XAA on i965 by default to avoid many rendering problems, closes: #451791. Interestingly, I've never been hit by these rendering problems with EXA, but I don't exactly have a 965G, but a 965GM. But the switch

Bug#451791: closed by Julien Cristau [EMAIL PROTECTED] (Bug#451791: fixed in xserver-xorg-video-intel 2:2.3.2-2+lenny3)

2008-08-27 Thread Julien Cristau
On Wed, Aug 27, 2008 at 19:25:17 +0200, Mike Hommey wrote: [ Brice Goglin ] * Add 02_xaa_by_default_on_i965.diff to switch back to XAA on i965 by default to avoid many rendering problems, closes: #451791. Interestingly, I've never been hit by these rendering problems with EXA,

Bug#481134: Please hint poppler-data for lenny inclusion

2008-08-27 Thread Luk Claes
Hideki Yamane wrote: On Sun, 24 Aug 2008 19:45:13 +0200 Luk Claes [EMAIL PROTECTED] wrote: unblocked Great thanks Luk! But, verrry sooorry, I've updated this poppler-data package before read this mail... changelog is below, 1 bug fix and trivial changes. poppler-data (0.2.0-2)

Processed: Re: Bug#496818: imagemagick 7:6.4.3.2.dfsg1-1(amd64/experimental): FTBFS: make[1]: *** No rule to make target `j'. Stop

2008-08-27 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: forcemerge 496212 496818 Bug#496212: imagemagick_7:6.4.3.2.dfsg1-1(ia64/experimental): FTBFS: No rule to make target `j'. Stop. Bug#496818: imagemagick 7:6.4.3.2.dfsg1-1(amd64/experimental): FTBFS: make[1]: *** No rule to make target `j'. Stop

  1   2   >